Legal

Privacy Policy

This policy explains how FilmiFeed may collect, use, and safeguard information when you visit the website.

Information we collect

We may collect personal information such as your name and email address when you contact us or choose to subscribe to an available service.

Our infrastructure processes ordinary request information, including IP addresses and request headers, to deliver and secure the website. FilmiFeed uses the privacy-preserving website measurement described below for aggregate traffic and performance reporting.

Reader accounts

When reader accounts are available and you choose Google sign-in, FilmiFeed requests only OpenID identity and email access. Google confirms a stable account identifier and a verified email address. The stable identifier remains the account identity. FilmiFeed stores an HMAC-protected form of that identifier, an internal random user ID, the verified email encrypted with AES-GCM, a separate non-unique HMAC of the email, private follow choices, saved story identifiers, notification preferences, and session records. It does not store your Google name, profile photo, access token, refresh token, or raw Google identifier.

Your follow list is not public and FilmiFeed does not show follower counts. Required account and security notices are service messages and cannot be turned off. Suggestion outcome email is enabled by default and can be turned off from your Account page. Following a person or title creates a private notification relationship, so related coverage email is also enabled by default and can be turned off at any time. Messages begin only after transactional delivery is active.

Transactional account email is separate from newsletter consent. It never subscribes you to the newsletter, and the newsletter does not read or prefill the verified Google email. Authorized Community administrators may reveal one exact account email for a support or privacy need only through an audited exact-member reveal. Reviewer access and account list responses do not include email.

When a signed-in member uses Community features, FilmiFeed may retain the two-character country code and short region code supplied by Cloudflare, plus when that coarse location was last observed. FilmiFeed does not retain the member's IP address, city, postal code, coordinates, ASN, raw browser user agent, or full timezone for member administration. Active Community administrators can view an exact member's coarse location, follow identifiers, session timestamps, and suggestion history. Full verified account email is hidden by default from directory responses. An administrator may use an exact verified email to find a matching account for support; the address is protected before database matching, never returned by the lookup, and the administrator account, result count, and time are audited. After a deliberate audited single-member reveal, one readable address may appear in the private member workspace; revealing another account or leaving that context clears the previous address. Each reveal records the administrator account, member account, and time. Reviewers cannot view member email, follows, or member detail. No bulk email export is provided.

Saved stories are private to your account and are used only to provide your reading list. FilmiFeed does not publish saved-story counts or use a save to subscribe you to email.

You can sign out or permanently delete the reader account from your Account page. Account deletion removes its sessions, encrypted account email, notification preferences, private follows, saved stories, profile suggestions, and transactional notification events.

If you suggest a profile update, FilmiFeed stores the selected profile and topic, your proposed change, the evidence link you provide, submission dates, and the editorial decision history with your internal account. Suggestions are private review records and never change a profile automatically.

Email newsletter

The optional email newsletter is separate from Google sign-in. If newsletter sign-up is available, a signed-in reader must manually enter an email address and select a separate, unchecked consent control. FilmiFeed does not request or prefill the Google account's email address for this purpose.

The approved email delivery provider processes the readable email address to deliver confirmation and newsletter messages. FilmiFeed's Community database does not store that readable address. It stores a domain-separated protected email fingerprint, an opaque provider reference, the consent version and source, coarse delivery and suppression states, timestamps, HMAC-protected confirmation or unsubscribe capabilities, and a minimal append-only consent and suppression record.

Visiting a confirmation or unsubscribe link does not change a preference. The reader must press the explicit confirmation or unsubscribe button, except for a standards-based one-click unsubscribe request sent directly by the email provider. Confirmation and unsubscribe links do not require a FilmiFeed login and should not be shared.

Deleting a reader account records the unsubscribe choice, revokes outstanding links, unlinks the newsletter record from the account, and completes or queues provider suppression. A minimal pseudonymous consent, audit, and suppression record remains so the address is not accidentally enrolled again and pending suppression can be retried.

Website analytics

FilmiFeed uses Cloudflare Web Analytics to understand aggregate website traffic and page performance. It may report page views and visits, public page paths, referrer information, country, device, browser, operating system, navigation type, load timing, and Core Web Vitals.

FilmiFeed does not send custom reading-time, scroll-depth, article-completion, internal-click, or internal-search events to this service. Cloudflare Web Analytics does not report URL query strings, including UTM campaign tags.

Cloudflare describes Web Analytics as privacy-first. Its analytics beacon does not use cookies, local storage, or fingerprinting to track visitors, and FilmiFeed does not create browser or session identifiers for it. Website analytics is separate from advertising.

How we use information

  • To operate and improve the website.
  • To respond to messages and provide requested updates.
  • To understand website traffic and reader interests.
  • To review, verify, and audit reader-submitted profile corrections.
  • To provide required account and security notices and the transactional notification choices you select.
  • To record separate newsletter consent and deliver requested email updates when that service is available.

Cookies

FilmiFeed no longer sets the former ff_aid, ff_sid, or ff_analytics_optout analytics cookies. During the transition, if your browser sends one of these retired cookies, FilmiFeed sends an expiry instruction to remove it.

FilmiFeed and its service providers may use cookies or similar technologies to remember preferences, operate the site, prevent fraud, and support advertising. Advertising cookies and choices are separate from Cloudflare Web Analytics.

If you use Following, FilmiFeed sets a host-only, HttpOnly, SameSite=Lax session cookie. It is Secure in non-local environments. The database stores only an HMAC of the random session token, not the cookie value itself.

Retention

Historical custom analytics collected before FilmiFeed retired its own collector may be retained under the previous limits: raw events for up to 30 days, daily aggregates for up to 25 months, and aggregated internal-search terms for up to 90 days. Cloudflare controls retention for Cloudflare Web Analytics. Imported aggregate Search Console and AdSense reporting rows may be retained for up to 16 months. Current URL and sitemap status records are retained while they remain useful and current.

Reader sessions expire after inactivity and have a fixed maximum lifetime. Encrypted account email, notification preferences, follow records, saved story identifiers, profile suggestions, and suggestion-review records remain until the account is deleted or FilmiFeed removes inactive community data under a future published retention schedule. Transactional events created while email delivery is off are held and will not be sent later. They are removed when the account is deleted.

When the newsletter is enabled, unconfirmed intake is limited to seven days and the email provider must enforce the same maximum for unconfirmed contacts. Minimal protected consent and suppression evidence is retained for the life of the newsletter program to prevent accidental re-enrolment and prove or retry an unsubscribe. An opaque provider reference is retained only while needed for that evidence or a pending delivery-provider command.

Limited community administrator and reviewer role records and user-administration action history may remain after account deletion for security and governance, but contain only opaque account references, bounded action details, and timestamps. They are retained for no more than 400 days once the required production retention job is active.

Advertising

FilmiFeed uses Google AdSense to display, limit, personalize where permitted, and measure advertising. Google and its advertising partners may process information such as cookies, device details, IP address, prior visits, and ad interactions for these purposes and to detect invalid traffic.

You can manage whether Google uses information to personalize ads in Google's ad settings. Google explains how it uses information from sites that use its services in its partner sites policy.

Where consent or an opt-out is required by law, FilmiFeed presents privacy choices for applicable advertising uses. The choices available to you depend on your location. Ads may be limited or non-personalized when the required permission has not been given.

Third-party services

Cloudflare provides FilmiFeed's infrastructure and Web Analytics and may process connection, request, and public page-performance information to deliver, protect, operate, and measure the site. FilmiFeed may also use Google sign-in, Google AdSense, Google Search Console, and approved email delivery providers if transactional notifications or the optional newsletter are enabled. Articles that contain an Instagram post may connect your browser to Instagram, a Meta service, so the embedded post can be displayed. Those services process information under their own terms. Advertising choices do not stop infrastructure processing required to serve and secure the website. Transactional and newsletter sending use separate service boundaries.

Data security

Verified account email is encrypted at the application layer before database storage. Its encryption key and HMAC secret are separate from each other and from Google identity and session secrets. Readable account email is excluded from reader session responses, reviewer responses, account lists, logs, and transactional outbox records. Reasonable measures are used to protect information from unauthorized access. No method of internet transmission or electronic storage is completely secure.

Changes to this policy

This policy may be updated as the website and its services change. The current version will be published on this page.

Contact

Questions about this policy can be sent to support@filmifeed.com.